Latest commit

History

55 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

LibreChat Admin Panel

A browser-based management interface for LibreChat. It connects to the same database as the main application and provides a GUI for tasks that would otherwise require editing librechat.yaml directly.

Features

  • Configuration management — View and edit all LibreChat settings through a dynamic, schema-driven form. New fields added to the schema appear automatically.
  • Role and group overrides — Apply configuration overrides scoped to specific roles or groups, with a priority-based cascade that determines the final resolved value for each user.
  • User and group administration — Create and manage groups, assign roles, and control access.
  • Authentication — Supports username/password login and OpenID SSO when enabled on the LibreChat instance.
  • Localization — Full multi-language support for all UI strings.
  • Accessibility — Keyboard navigable with ARIA regions, focus management, and screen reader support.

Getting started

Local development

cp .env.example .env # then edit .env
bun install
bun dev # http://localhost:3000

Docker

cp .env.example .env
# Set SESSION_SECRET (min 32 chars)# Set VITE_API_BASE_URL=http://host.docker.internal:3080
docker compose up -d # builds and starts on http://localhost:3000
docker compose down # stop

Note: Inside Docker, localhost refers to the container, not your machine. Use http://host.docker.internal:3080 for VITE_API_BASE_URL to reach LibreChat running on the host.

Environment variables

VariableRequiredDefaultDescription
PORTNo3000Port the admin panel listens on
SESSION_SECRETYes (always required in Docker)Dev fallback only when running bun dev locally; no default in the Docker imageEncryption key for sessions (min 32 chars)
VITE_API_BASE_URLYes (Docker)http://localhost:3080 (local dev only)LibreChat API server URL; use http://host.docker.internal:<port> in Docker
VITE_BASE_PATHNo/URL subpath to serve the panel under (e.g., /adminpanel). Must match at build time and runtime
API_SERVER_URLNoFalls back to VITE_API_BASE_URLServer-side LibreChat API URL when the container reaches LibreChat differently than the browser
ADMIN_SSO_ONLYNofalseHide email/password form, SSO only
ADMIN_SSO_ENABLEDNotrueSet false to hide the SSO button (and auto-redirect) while keeping email/password login
ADMIN_SESSION_IDLE_TIMEOUT_MSNo1800000 (30 min)Session idle timeout in ms
SESSION_COOKIE_SECURENotrue in production, false otherwiseSet false only for plain-HTTP deployments so the browser keeps the admin session cookie

For OpenID SSO, the admin panel stores a short-lived PKCE verifier in the admin-session cookie before redirecting to LibreChat. If the admin panel is served over plain HTTP while running in production mode, browsers reject a Secure session cookie and the callback cannot complete the PKCE exchange. In that deployment shape, set SESSION_COOKIE_SECURE=false on the admin panel. Set the same override on LibreChat itself when LibreChat is also reached over plain HTTP, so its OAuth and auth cookies are not dropped either.

Standalone Docker build

docker build -t librechat-admin-panel .
docker run -p 3000:3000 \
--add-host=host.docker.internal:host-gateway \
-e SESSION_SECRET=your-secret-here-at-least-32-characters \
-e VITE_API_BASE_URL=http://host.docker.internal:3080 \
-e SESSION_COOKIE_SECURE=false \
librechat-admin-panel
# To serve under a subpath (e.g., /adminpanel):
docker build -t librechat-admin-panel --build-arg VITE_BASE_PATH=/adminpanel .
docker run -p 3000:3000 \
--add-host=host.docker.internal:host-gateway \
-e SESSION_SECRET=your-secret-here-at-least-32-characters \
-e VITE_API_BASE_URL=http://host.docker.internal:3080 \
-e VITE_BASE_PATH=/adminpanel \
librechat-admin-panel

About

A standalone application for managing LibreChat configurations and permissions

Resources

Stars

141 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Latest commit

History

55 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

LibreChat Admin Panel

A browser-based management interface for LibreChat. It connects to the same database as the main application and provides a GUI for tasks that would otherwise require editing librechat.yaml directly.

Features

  • Configuration management — View and edit all LibreChat settings through a dynamic, schema-driven form. New fields added to the schema appear automatically.
  • Role and group overrides — Apply configuration overrides scoped to specific roles or groups, with a priority-based cascade that determines the final resolved value for each user.
  • User and group administration — Create and manage groups, assign roles, and control access.
  • Authentication — Supports username/password login and OpenID SSO when enabled on the LibreChat instance.
  • Localization — Full multi-language support for all UI strings.
  • Accessibility — Keyboard navigable with ARIA regions, focus management, and screen reader support.

Getting started

Local development

cp .env.example .env # then edit .env
bun install
bun dev # http://localhost:3000

Docker

cp .env.example .env
# Set SESSION_SECRET (min 32 chars)# Set VITE_API_BASE_URL=http://host.docker.internal:3080
docker compose up -d # builds and starts on http://localhost:3000
docker compose down # stop

Note: Inside Docker, localhost refers to the container, not your machine. Use http://host.docker.internal:3080 for VITE_API_BASE_URL to reach LibreChat running on the host.

Environment variables

VariableRequiredDefaultDescription
PORTNo3000Port the admin panel listens on
SESSION_SECRETYes (always required in Docker)Dev fallback only when running bun dev locally; no default in the Docker imageEncryption key for sessions (min 32 chars)
VITE_API_BASE_URLYes (Docker)http://localhost:3080 (local dev only)LibreChat API server URL; use http://host.docker.internal:<port> in Docker
VITE_BASE_PATHNo/URL subpath to serve the panel under (e.g., /adminpanel). Must match at build time and runtime
API_SERVER_URLNoFalls back to VITE_API_BASE_URLServer-side LibreChat API URL when the container reaches LibreChat differently than the browser
ADMIN_SSO_ONLYNofalseHide email/password form, SSO only
ADMIN_SSO_ENABLEDNotrueSet false to hide the SSO button (and auto-redirect) while keeping email/password login
ADMIN_SESSION_IDLE_TIMEOUT_MSNo1800000 (30 min)Session idle timeout in ms
SESSION_COOKIE_SECURENotrue in production, false otherwiseSet false only for plain-HTTP deployments so the browser keeps the admin session cookie

For OpenID SSO, the admin panel stores a short-lived PKCE verifier in the admin-session cookie before redirecting to LibreChat. If the admin panel is served over plain HTTP while running in production mode, browsers reject a Secure session cookie and the callback cannot complete the PKCE exchange. In that deployment shape, set SESSION_COOKIE_SECURE=false on the admin panel. Set the same override on LibreChat itself when LibreChat is also reached over plain HTTP, so its OAuth and auth cookies are not dropped either.

Standalone Docker build

docker build -t librechat-admin-panel .
docker run -p 3000:3000 \
--add-host=host.docker.internal:host-gateway \
-e SESSION_SECRET=your-secret-here-at-least-32-characters \
-e VITE_API_BASE_URL=http://host.docker.internal:3080 \
-e SESSION_COOKIE_SECURE=false \
librechat-admin-panel
# To serve under a subpath (e.g., /adminpanel):
docker build -t librechat-admin-panel --build-arg VITE_BASE_PATH=/adminpanel .
docker run -p 3000:3000 \
--add-host=host.docker.internal:host-gateway \
-e SESSION_SECRET=your-secret-here-at-least-32-characters \
-e VITE_API_BASE_URL=http://host.docker.internal:3080 \
-e VITE_BASE_PATH=/adminpanel \
librechat-admin-panel

About

A standalone application for managing LibreChat configurations and permissions

Resources

Stars

141 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

55 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

LibreChat Admin Panel

A browser-based management interface for LibreChat. It connects to the same database as the main application and provides a GUI for tasks that would otherwise require editing librechat.yaml directly.

Features

  • Configuration management — View and edit all LibreChat settings through a dynamic, schema-driven form. New fields added to the schema appear automatically.
  • Role and group overrides — Apply configuration overrides scoped to specific roles or groups, with a priority-based cascade that determines the final resolved value for each user.
  • User and group administration — Create and manage groups, assign roles, and control access.
  • Authentication — Supports username/password login and OpenID SSO when enabled on the LibreChat instance.
  • Localization — Full multi-language support for all UI strings.
  • Accessibility — Keyboard navigable with ARIA regions, focus management, and screen reader support.

Getting started

Local development

cp .env.example .env # then edit .env
bun install
bun dev # http://localhost:3000

Docker

cp .env.example .env
# Set SESSION_SECRET (min 32 chars)# Set VITE_API_BASE_URL=http://host.docker.internal:3080
docker compose up -d # builds and starts on http://localhost:3000
docker compose down # stop

Note: Inside Docker, localhost refers to the container, not your machine. Use http://host.docker.internal:3080 for VITE_API_BASE_URL to reach LibreChat running on the host.

Environment variables

VariableRequiredDefaultDescription
PORTNo3000Port the admin panel listens on
SESSION_SECRETYes (always required in Docker)Dev fallback only when running bun dev locally; no default in the Docker imageEncryption key for sessions (min 32 chars)
VITE_API_BASE_URLYes (Docker)http://localhost:3080 (local dev only)LibreChat API server URL; use http://host.docker.internal:<port> in Docker
VITE_BASE_PATHNo/URL subpath to serve the panel under (e.g., /adminpanel). Must match at build time and runtime
API_SERVER_URLNoFalls back to VITE_API_BASE_URLServer-side LibreChat API URL when the container reaches LibreChat differently than the browser
ADMIN_SSO_ONLYNofalseHide email/password form, SSO only
ADMIN_SSO_ENABLEDNotrueSet false to hide the SSO button (and auto-redirect) while keeping email/password login
ADMIN_SESSION_IDLE_TIMEOUT_MSNo1800000 (30 min)Session idle timeout in ms
SESSION_COOKIE_SECURENotrue in production, false otherwiseSet false only for plain-HTTP deployments so the browser keeps the admin session cookie

For OpenID SSO, the admin panel stores a short-lived PKCE verifier in the admin-session cookie before redirecting to LibreChat. If the admin panel is served over plain HTTP while running in production mode, browsers reject a Secure session cookie and the callback cannot complete the PKCE exchange. In that deployment shape, set SESSION_COOKIE_SECURE=false on the admin panel. Set the same override on LibreChat itself when LibreChat is also reached over plain HTTP, so its OAuth and auth cookies are not dropped either.

Standalone Docker build

docker build -t librechat-admin-panel .
docker run -p 3000:3000 \
--add-host=host.docker.internal:host-gateway \
-e SESSION_SECRET=your-secret-here-at-least-32-characters \
-e VITE_API_BASE_URL=http://host.docker.internal:3080 \
-e SESSION_COOKIE_SECURE=false \
librechat-admin-panel
# To serve under a subpath (e.g., /adminpanel):
docker build -t librechat-admin-panel --build-arg VITE_BASE_PATH=/adminpanel .
docker run -p 3000:3000 \
--add-host=host.docker.internal:host-gateway \
-e SESSION_SECRET=your-secret-here-at-least-32-characters \
-e VITE_API_BASE_URL=http://host.docker.internal:3080 \
-e VITE_BASE_PATH=/adminpanel \
librechat-admin-panel

About

A standalone application for managing LibreChat configurations and permissions

Resources

Stars

141 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

55 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

LibreChat Admin Panel

A browser-based management interface for LibreChat. It connects to the same database as the main application and provides a GUI for tasks that would otherwise require editing librechat.yaml directly.

Features

  • Configuration management — View and edit all LibreChat settings through a dynamic, schema-driven form. New fields added to the schema appear automatically.
  • Role and group overrides — Apply configuration overrides scoped to specific roles or groups, with a priority-based cascade that determines the final resolved value for each user.
  • User and group administration — Create and manage groups, assign roles, and control access.
  • Authentication — Supports username/password login and OpenID SSO when enabled on the LibreChat instance.
  • Localization — Full multi-language support for all UI strings.
  • Accessibility — Keyboard navigable with ARIA regions, focus management, and screen reader support.

Getting started

Local development

cp .env.example .env # then edit .env
bun install
bun dev # http://localhost:3000

Docker

cp .env.example .env
# Set SESSION_SECRET (min 32 chars)# Set VITE_API_BASE_URL=http://host.docker.internal:3080
docker compose up -d # builds and starts on http://localhost:3000
docker compose down # stop

Note: Inside Docker, localhost refers to the container, not your machine. Use http://host.docker.internal:3080 for VITE_API_BASE_URL to reach LibreChat running on the host.

Environment variables

VariableRequiredDefaultDescription
PORTNo3000Port the admin panel listens on
SESSION_SECRETYes (always required in Docker)Dev fallback only when running bun dev locally; no default in the Docker imageEncryption key for sessions (min 32 chars)
VITE_API_BASE_URLYes (Docker)http://localhost:3080 (local dev only)LibreChat API server URL; use http://host.docker.internal:<port> in Docker
VITE_BASE_PATHNo/URL subpath to serve the panel under (e.g., /adminpanel). Must match at build time and runtime
API_SERVER_URLNoFalls back to VITE_API_BASE_URLServer-side LibreChat API URL when the container reaches LibreChat differently than the browser
ADMIN_SSO_ONLYNofalseHide email/password form, SSO only
ADMIN_SSO_ENABLEDNotrueSet false to hide the SSO button (and auto-redirect) while keeping email/password login
ADMIN_SESSION_IDLE_TIMEOUT_MSNo1800000 (30 min)Session idle timeout in ms
SESSION_COOKIE_SECURENotrue in production, false otherwiseSet false only for plain-HTTP deployments so the browser keeps the admin session cookie

For OpenID SSO, the admin panel stores a short-lived PKCE verifier in the admin-session cookie before redirecting to LibreChat. If the admin panel is served over plain HTTP while running in production mode, browsers reject a Secure session cookie and the callback cannot complete the PKCE exchange. In that deployment shape, set SESSION_COOKIE_SECURE=false on the admin panel. Set the same override on LibreChat itself when LibreChat is also reached over plain HTTP, so its OAuth and auth cookies are not dropped either.

Standalone Docker build

docker build -t librechat-admin-panel .
docker run -p 3000:3000 \
--add-host=host.docker.internal:host-gateway \
-e SESSION_SECRET=your-secret-here-at-least-32-characters \
-e VITE_API_BASE_URL=http://host.docker.internal:3080 \
-e SESSION_COOKIE_SECURE=false \
librechat-admin-panel
# To serve under a subpath (e.g., /adminpanel):
docker build -t librechat-admin-panel --build-arg VITE_BASE_PATH=/adminpanel .
docker run -p 3000:3000 \
--add-host=host.docker.internal:host-gateway \
-e SESSION_SECRET=your-secret-here-at-least-32-characters \
-e VITE_API_BASE_URL=http://host.docker.internal:3080 \
-e VITE_BASE_PATH=/adminpanel \
librechat-admin-panel

About

A standalone application for managing LibreChat configurations and permissions

Resources

Stars

141 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Latest commit

History

55 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

LibreChat Admin Panel

A browser-based management interface for LibreChat. It connects to the same database as the main application and provides a GUI for tasks that would otherwise require editing librechat.yaml directly.

Features

  • Configuration management — View and edit all LibreChat settings through a dynamic, schema-driven form. New fields added to the schema appear automatically.
  • Role and group overrides — Apply configuration overrides scoped to specific roles or groups, with a priority-based cascade that determines the final resolved value for each user.
  • User and group administration — Create and manage groups, assign roles, and control access.
  • Authentication — Supports username/password login and OpenID SSO when enabled on the LibreChat instance.
  • Localization — Full multi-language support for all UI strings.
  • Accessibility — Keyboard navigable with ARIA regions, focus management, and screen reader support.

Getting started

Local development

cp .env.example .env # then edit .env
bun install
bun dev # http://localhost:3000

Docker

cp .env.example .env
# Set SESSION_SECRET (min 32 chars)# Set VITE_API_BASE_URL=http://host.docker.internal:3080
docker compose up -d # builds and starts on http://localhost:3000
docker compose down # stop

Note: Inside Docker, localhost refers to the container, not your machine. Use http://host.docker.internal:3080 for VITE_API_BASE_URL to reach LibreChat running on the host.

Environment variables

VariableRequiredDefaultDescription
PORTNo3000Port the admin panel listens on
SESSION_SECRETYes (always required in Docker)Dev fallback only when running bun dev locally; no default in the Docker imageEncryption key for sessions (min 32 chars)
VITE_API_BASE_URLYes (Docker)http://localhost:3080 (local dev only)LibreChat API server URL; use http://host.docker.internal:<port> in Docker
VITE_BASE_PATHNo/URL subpath to serve the panel under (e.g., /adminpanel). Must match at build time and runtime
API_SERVER_URLNoFalls back to VITE_API_BASE_URLServer-side LibreChat API URL when the container reaches LibreChat differently than the browser
ADMIN_SSO_ONLYNofalseHide email/password form, SSO only
ADMIN_SSO_ENABLEDNotrueSet false to hide the SSO button (and auto-redirect) while keeping email/password login
ADMIN_SESSION_IDLE_TIMEOUT_MSNo1800000 (30 min)Session idle timeout in ms
SESSION_COOKIE_SECURENotrue in production, false otherwiseSet false only for plain-HTTP deployments so the browser keeps the admin session cookie

For OpenID SSO, the admin panel stores a short-lived PKCE verifier in the admin-session cookie before redirecting to LibreChat. If the admin panel is served over plain HTTP while running in production mode, browsers reject a Secure session cookie and the callback cannot complete the PKCE exchange. In that deployment shape, set SESSION_COOKIE_SECURE=false on the admin panel. Set the same override on LibreChat itself when LibreChat is also reached over plain HTTP, so its OAuth and auth cookies are not dropped either.

Standalone Docker build

docker build -t librechat-admin-panel .
docker run -p 3000:3000 \
--add-host=host.docker.internal:host-gateway \
-e SESSION_SECRET=your-secret-here-at-least-32-characters \
-e VITE_API_BASE_URL=http://host.docker.internal:3080 \
-e SESSION_COOKIE_SECURE=false \
librechat-admin-panel
# To serve under a subpath (e.g., /adminpanel):
docker build -t librechat-admin-panel --build-arg VITE_BASE_PATH=/adminpanel .
docker run -p 3000:3000 \
--add-host=host.docker.internal:host-gateway \
-e SESSION_SECRET=your-secret-here-at-least-32-characters \
-e VITE_API_BASE_URL=http://host.docker.internal:3080 \
-e VITE_BASE_PATH=/adminpanel \
librechat-admin-panel

About

A standalone application for managing LibreChat configurations and permissions

Resources

Stars

141 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

55 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

LibreChat Admin Panel

A browser-based management interface for LibreChat. It connects to the same database as the main application and provides a GUI for tasks that would otherwise require editing librechat.yaml directly.

Features

  • Configuration management — View and edit all LibreChat settings through a dynamic, schema-driven form. New fields added to the schema appear automatically.
  • Role and group overrides — Apply configuration overrides scoped to specific roles or groups, with a priority-based cascade that determines the final resolved value for each user.
  • User and group administration — Create and manage groups, assign roles, and control access.
  • Authentication — Supports username/password login and OpenID SSO when enabled on the LibreChat instance.
  • Localization — Full multi-language support for all UI strings.
  • Accessibility — Keyboard navigable with ARIA regions, focus management, and screen reader support.

Getting started

Local development

cp .env.example .env # then edit .env
bun install
bun dev # http://localhost:3000

Docker

cp .env.example .env
# Set SESSION_SECRET (min 32 chars)# Set VITE_API_BASE_URL=http://host.docker.internal:3080
docker compose up -d # builds and starts on http://localhost:3000
docker compose down # stop

Note: Inside Docker, localhost refers to the container, not your machine. Use http://host.docker.internal:3080 for VITE_API_BASE_URL to reach LibreChat running on the host.

Environment variables

VariableRequiredDefaultDescription
PORTNo3000Port the admin panel listens on
SESSION_SECRETYes (always required in Docker)Dev fallback only when running bun dev locally; no default in the Docker imageEncryption key for sessions (min 32 chars)
VITE_API_BASE_URLYes (Docker)http://localhost:3080 (local dev only)LibreChat API server URL; use http://host.docker.internal:<port> in Docker
VITE_BASE_PATHNo/URL subpath to serve the panel under (e.g., /adminpanel). Must match at build time and runtime
API_SERVER_URLNoFalls back to VITE_API_BASE_URLServer-side LibreChat API URL when the container reaches LibreChat differently than the browser
ADMIN_SSO_ONLYNofalseHide email/password form, SSO only
ADMIN_SSO_ENABLEDNotrueSet false to hide the SSO button (and auto-redirect) while keeping email/password login
ADMIN_SESSION_IDLE_TIMEOUT_MSNo1800000 (30 min)Session idle timeout in ms
SESSION_COOKIE_SECURENotrue in production, false otherwiseSet false only for plain-HTTP deployments so the browser keeps the admin session cookie

For OpenID SSO, the admin panel stores a short-lived PKCE verifier in the admin-session cookie before redirecting to LibreChat. If the admin panel is served over plain HTTP while running in production mode, browsers reject a Secure session cookie and the callback cannot complete the PKCE exchange. In that deployment shape, set SESSION_COOKIE_SECURE=false on the admin panel. Set the same override on LibreChat itself when LibreChat is also reached over plain HTTP, so its OAuth and auth cookies are not dropped either.

Standalone Docker build

docker build -t librechat-admin-panel .
docker run -p 3000:3000 \
--add-host=host.docker.internal:host-gateway \
-e SESSION_SECRET=your-secret-here-at-least-32-characters \
-e VITE_API_BASE_URL=http://host.docker.internal:3080 \
-e SESSION_COOKIE_SECURE=false \
librechat-admin-panel
# To serve under a subpath (e.g., /adminpanel):
docker build -t librechat-admin-panel --build-arg VITE_BASE_PATH=/adminpanel .
docker run -p 3000:3000 \
--add-host=host.docker.internal:host-gateway \
-e SESSION_SECRET=your-secret-here-at-least-32-characters \
-e VITE_API_BASE_URL=http://host.docker.internal:3080 \
-e VITE_BASE_PATH=/adminpanel \
librechat-admin-panel

About

A standalone application for managing LibreChat configurations and permissions

Resources

Stars

141 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

55 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

LibreChat Admin Panel

A browser-based management interface for LibreChat. It connects to the same database as the main application and provides a GUI for tasks that would otherwise require editing librechat.yaml directly.

Features

  • Configuration management — View and edit all LibreChat settings through a dynamic, schema-driven form. New fields added to the schema appear automatically.
  • Role and group overrides — Apply configuration overrides scoped to specific roles or groups, with a priority-based cascade that determines the final resolved value for each user.
  • User and group administration — Create and manage groups, assign roles, and control access.
  • Authentication — Supports username/password login and OpenID SSO when enabled on the LibreChat instance.
  • Localization — Full multi-language support for all UI strings.
  • Accessibility — Keyboard navigable with ARIA regions, focus management, and screen reader support.

Getting started

Local development

cp .env.example .env # then edit .env
bun install
bun dev # http://localhost:3000

Docker

cp .env.example .env
# Set SESSION_SECRET (min 32 chars)# Set VITE_API_BASE_URL=http://host.docker.internal:3080
docker compose up -d # builds and starts on http://localhost:3000
docker compose down # stop

Note: Inside Docker, localhost refers to the container, not your machine. Use http://host.docker.internal:3080 for VITE_API_BASE_URL to reach LibreChat running on the host.

Environment variables

VariableRequiredDefaultDescription
PORTNo3000Port the admin panel listens on
SESSION_SECRETYes (always required in Docker)Dev fallback only when running bun dev locally; no default in the Docker imageEncryption key for sessions (min 32 chars)
VITE_API_BASE_URLYes (Docker)http://localhost:3080 (local dev only)LibreChat API server URL; use http://host.docker.internal:<port> in Docker
VITE_BASE_PATHNo/URL subpath to serve the panel under (e.g., /adminpanel). Must match at build time and runtime
API_SERVER_URLNoFalls back to VITE_API_BASE_URLServer-side LibreChat API URL when the container reaches LibreChat differently than the browser
ADMIN_SSO_ONLYNofalseHide email/password form, SSO only
ADMIN_SSO_ENABLEDNotrueSet false to hide the SSO button (and auto-redirect) while keeping email/password login
ADMIN_SESSION_IDLE_TIMEOUT_MSNo1800000 (30 min)Session idle timeout in ms
SESSION_COOKIE_SECURENotrue in production, false otherwiseSet false only for plain-HTTP deployments so the browser keeps the admin session cookie

For OpenID SSO, the admin panel stores a short-lived PKCE verifier in the admin-session cookie before redirecting to LibreChat. If the admin panel is served over plain HTTP while running in production mode, browsers reject a Secure session cookie and the callback cannot complete the PKCE exchange. In that deployment shape, set SESSION_COOKIE_SECURE=false on the admin panel. Set the same override on LibreChat itself when LibreChat is also reached over plain HTTP, so its OAuth and auth cookies are not dropped either.

Standalone Docker build

docker build -t librechat-admin-panel .
docker run -p 3000:3000 \
--add-host=host.docker.internal:host-gateway \
-e SESSION_SECRET=your-secret-here-at-least-32-characters \
-e VITE_API_BASE_URL=http://host.docker.internal:3080 \
-e SESSION_COOKIE_SECURE=false \
librechat-admin-panel
# To serve under a subpath (e.g., /adminpanel):
docker build -t librechat-admin-panel --build-arg VITE_BASE_PATH=/adminpanel .
docker run -p 3000:3000 \
--add-host=host.docker.internal:host-gateway \
-e SESSION_SECRET=your-secret-here-at-least-32-characters \
-e VITE_API_BASE_URL=http://host.docker.internal:3080 \
-e VITE_BASE_PATH=/adminpanel \
librechat-admin-panel

About

A standalone application for managing LibreChat configurations and permissions

Resources

Stars

141 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Latest commit

History

55 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

LibreChat Admin Panel

A browser-based management interface for LibreChat. It connects to the same database as the main application and provides a GUI for tasks that would otherwise require editing librechat.yaml directly.

Features

  • Configuration management — View and edit all LibreChat settings through a dynamic, schema-driven form. New fields added to the schema appear automatically.
  • Role and group overrides — Apply configuration overrides scoped to specific roles or groups, with a priority-based cascade that determines the final resolved value for each user.
  • User and group administration — Create and manage groups, assign roles, and control access.
  • Authentication — Supports username/password login and OpenID SSO when enabled on the LibreChat instance.
  • Localization — Full multi-language support for all UI strings.
  • Accessibility — Keyboard navigable with ARIA regions, focus management, and screen reader support.

Getting started

Local development

cp .env.example .env # then edit .env
bun install
bun dev # http://localhost:3000

Docker

cp .env.example .env
# Set SESSION_SECRET (min 32 chars)# Set VITE_API_BASE_URL=http://host.docker.internal:3080
docker compose up -d # builds and starts on http://localhost:3000
docker compose down # stop

Note: Inside Docker, localhost refers to the container, not your machine. Use http://host.docker.internal:3080 for VITE_API_BASE_URL to reach LibreChat running on the host.

Environment variables

VariableRequiredDefaultDescription
PORTNo3000Port the admin panel listens on
SESSION_SECRETYes (always required in Docker)Dev fallback only when running bun dev locally; no default in the Docker imageEncryption key for sessions (min 32 chars)
VITE_API_BASE_URLYes (Docker)http://localhost:3080 (local dev only)LibreChat API server URL; use http://host.docker.internal:<port> in Docker
VITE_BASE_PATHNo/URL subpath to serve the panel under (e.g., /adminpanel). Must match at build time and runtime
API_SERVER_URLNoFalls back to VITE_API_BASE_URLServer-side LibreChat API URL when the container reaches LibreChat differently than the browser
ADMIN_SSO_ONLYNofalseHide email/password form, SSO only
ADMIN_SSO_ENABLEDNotrueSet false to hide the SSO button (and auto-redirect) while keeping email/password login
ADMIN_SESSION_IDLE_TIMEOUT_MSNo1800000 (30 min)Session idle timeout in ms
SESSION_COOKIE_SECURENotrue in production, false otherwiseSet false only for plain-HTTP deployments so the browser keeps the admin session cookie

For OpenID SSO, the admin panel stores a short-lived PKCE verifier in the admin-session cookie before redirecting to LibreChat. If the admin panel is served over plain HTTP while running in production mode, browsers reject a Secure session cookie and the callback cannot complete the PKCE exchange. In that deployment shape, set SESSION_COOKIE_SECURE=false on the admin panel. Set the same override on LibreChat itself when LibreChat is also reached over plain HTTP, so its OAuth and auth cookies are not dropped either.

Standalone Docker build

docker build -t librechat-admin-panel .
docker run -p 3000:3000 \
--add-host=host.docker.internal:host-gateway \
-e SESSION_SECRET=your-secret-here-at-least-32-characters \
-e VITE_API_BASE_URL=http://host.docker.internal:3080 \
-e SESSION_COOKIE_SECURE=false \
librechat-admin-panel
# To serve under a subpath (e.g., /adminpanel):
docker build -t librechat-admin-panel --build-arg VITE_BASE_PATH=/adminpanel .
docker run -p 3000:3000 \
--add-host=host.docker.internal:host-gateway \
-e SESSION_SECRET=your-secret-here-at-least-32-characters \
-e VITE_API_BASE_URL=http://host.docker.internal:3080 \
-e VITE_BASE_PATH=/adminpanel \
librechat-admin-panel

About

A standalone application for managing LibreChat configurations and permissions

Resources

Stars

141 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages